Ledger CTO says Ethereum app flaw was fixed two weeks before public claims

Ledger CTO says Ethereum app flaw was fixed two weeks before public claims

N
News Editor
2026-08-27 03:05:06
Ledger Chief Technology Officer Charles Guillemet said recent claims about a vulnerability in the company’s Ethereum app have been presented in a misleading way. In a post published on Aug. 27, Guillemet said Ledger had previously identified a flaw tied to parts of its Clear Signing flow, but the issue had already been discovered internally by Donjon, Ledger’s security research team, using an AI-driven vulnerability research tool. He said the fix had been completed and deployed two weeks earlier. Guillemet added that users who update their Ledger device firmware and app are protected. He also criticized the security company behind the public claims, saying it contacted Ledger’s bug bounty program only after the patch had already been released. According to him, the firm did not follow responsible disclosure procedures, did not communicate with the bug bounty team, and later published material implying the problem remained unresolved. He argued that such behavior creates fear rather than advancing security research. Guillemet also said AI is changing cybersecurity for both attackers and defenders, but AI-based security work only improves the broader ecosystem when it follows basic principles such as responsible disclosure and verification before publication.

Ledger Chief Technology Officer Charles Guillemet responded on Aug. 27 to what he described as recent FUD surrounding the hardware wallet maker, after a smart contract security company claimed it had found a vulnerability in Ledger’s Ethereum app.

Ledger says the flaw had already been patched

Guillemet said the Ledger Ethereum app had indeed contained a vulnerability related to parts of the Clear Signing process. He said the issue was identified by Donjon, Ledger’s in-house security research team, using an AI-driven vulnerability research tool, and that the patch had been completed and deployed two weeks earlier.

According to Guillemet, users are protected as long as they promptly update their Ledger device firmware and the app.

Disclosure process criticized

Guillemet said the security company involved only contacted Ledger’s bug bounty program after the fix had already been completed. He said the firm did not follow responsible disclosure procedures and did not communicate with the bug bounty team, but later published content suggesting the issue was still unresolved.

He said that kind of conduct was not genuine security research, but an attempt to stir panic and attract attention.

Users told to keep software updated

Guillemet also said AI is changing cybersecurity, with both attackers and defenders able to use AI to improve efficiency. At the same time, he said AI-driven security research can improve the ecosystem only when it follows basic security principles such as responsible disclosure and verification before publication.

He ended by advising Ledger users to keep device firmware, Ledger apps, and related software on the latest versions. Doing so, he said, automatically delivers the latest security fixes and research results, and users do not need to be affected by the related FUD as long as they update promptly and maintain good security practices.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.